We are seeking a DevSecOps Engineer to embed security into our cloud-native development workflows and corporate IT environment. The role requires a pragmatic security mindset, balancing strong controls with developer velocity in a regulated environment.
Requirements
- 3–6 years of experience in DevSecOps, cloud security, or platform security roles.
- Strong hands-on experience securing AWS environments, including IAM, VPCs, CloudTrail, GuardDuty, Security Hub, and encryption services.
- Proven experience integrating security tooling into CI/CD pipelines, including SonarQube for static analysis and code quality enforcement.
- Hands-on experience with SIEM and security monitoring tools, including Microsoft Sentinel or equivalent platforms.
- Experience with container, dependency, and secrets security tooling.
- Strong understanding of secure software development lifecycle (SSDLC) principles and shift-left security practices.
- Experience securing Microsoft 365 environments, including Entra ID (Azure AD), Conditional Access, Defender, and email security.
- Familiarity with ISO 27001 concepts, including risk management, control implementation, evidence collection, and audit support.
- Experience working in regulated environments such as financial services, fintech, or similar industries.
- Strong analytical and problem-solving skills, with the ability to balance security risk, usability, and delivery speed.
- Clear written and verbal communication skills, with the ability to collaborate effectively with engineering, IT, and compliance teams.